PT-2018-16920 · WordPress · Wpglobus

Published

2018-01-12

·

Updated

2022-05-14

·

CVE-2018-5363

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WPGlobus plugin version 1.9.6
Description The issue concerns a cross-site scripting (XSS) problem. It is exploited via the wpglobus option[enabled languages][en] or wpglobus option[enabled languages][fr] (or any other language) parameter to the wp-admin/options.php endpoint.
Recommendations For WPGlobus plugin version 1.9.6, consider disabling access to the wp-admin/options.php endpoint until a patch is available, or avoid using the wpglobus option[enabled languages][en] and wpglobus option[enabled languages][fr] parameters in this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5363
GHSA-GPQ5-VQVX-CH9J

Affected Products

Wpglobus